Many businesses begin preparing for SMB1001 certification expecting the biggest challenge to be technology.
They assume the assessment will uncover missing security tools, outdated systems or major vulnerabilities.
In reality, that's rarely what causes the most difficulty.
Most organisations pursuing SMB1001 already have security controls in place. They have backups running, endpoint protection deployed and multi-factor authentication (MFA) enabled. What often creates challenges during an assessment is something much less obvious.
Documentation.
Accountability.
Evidence.
Governance.
The good news is that the most common SMB1001 audit findings are usually preventable once organisations understand what assessors are actually looking for.
If you're still early in your certification journey, our guide on How to Prepare for SMB1001 Certification provides an overview of the certification process and the key areas businesses should focus on
"Many businesses assume they'll need to implement lots of new technology before an assessment. More often than not, the challenge is demonstrating that existing controls are documented, managed and consistently followed."
Chris Mannering, Director, Step Fwd IT
One of the biggest misconceptions about SMB1001 certification is that it's primarily a technical assessment.
Technology certainly matters, but SMB1001 is designed to evaluate how cybersecurity is managed across the organisation.
An organisation can have excellent technical controls and still experience difficulties during an assessment if it cannot demonstrate:
This distinction is one of the major differences between SMB1001 and the Essential Eight.
As we discussed in our SMB1001 vs Essential Eight article, SMB1001 focuses on broader organisational maturity rather than purely technical security controls.
The question assessors ask is not:
"Do you have security?"
It's:
"Can you demonstrate how security is being managed?"
| Common Finding | Why It Creates Problems |
| Missing evidence | Security activities can't be verified |
| Outdated policies | Documentation no longer reflects reality |
| Unclear ownership | Critical activities fall through the cracks |
| Weak user access management | Increased security and compliance risk |
| Informal risk management | Decisions can't be clearly demonstrated |
| Untested backups | Recovery capability is unknown |
| Treating certification as a project | Improvements become difficult to sustain |
If there's one theme that appears consistently during certification preparation, it's documentation.
Many businesses are doing the right things.
They simply haven't documented them.
Policies may exist but haven't been updated in years.
Procedures may be followed consistently but live in the heads of long-serving employees rather than in documented processes.
Risk discussions may occur regularly, but no formal records exist.
From the business's perspective, cybersecurity is functioning.
From an assessor's perspective, there is very little evidence to support that conclusion.
Not every assessment is identical, but businesses should expect to produce evidence such as:
The strongest organisations aren't necessarily the ones with the most documentation.
They're the ones whose documentation accurately reflects reality.
One of the most common conversations during certification preparation sounds something like this:
Assessor: "How often do you review user access?"
Business: "We already do that."
Assessor: "Can you provide evidence of those reviews?"
Business: "Not really."
The same issue appears across many security activities:
The lesson is simple:
Doing the activity is important. Being able to demonstrate it happened is equally important.
In many cases, the gap between a successful certification outcome and an audit finding comes down to evidence.
As organisations grow, cybersecurity responsibilities often become spread across multiple people.
Management owns some decisions.
Internal staff own others.
An IT provider manages various technical controls.
On paper, everyone is involved.
In reality, ownership can become unclear.
Policy reviews get delayed.
Access approvals happen inconsistently.
Risk reviews don't take place.
Cybersecurity becomes everyone's responsibility.
Which often means it becomes nobody's responsibility.
"One of the biggest indicators of cybersecurity maturity isn't the technology a business uses. It's whether responsibilities are clearly understood and consistently followed."
Chris Mannering, Director, Step Fwd IT
Organisations that perform well during assessments usually have clear accountability structures that define who is responsible for governance, risk management and continual improvement.
Many organisations think about cybersecurity in terms of threats and technology.
SMB1001 encourages organisations to think about risk.
This subtle difference is important.
Risk management helps businesses decide:
Without a structured risk management process, cybersecurity decisions often become reactive rather than strategic.
This is why assessors place significant emphasis on risk registers, risk reviews and documented decision-making.
The strongest cybersecurity programs aren't necessarily those that spend the most money.
They're the ones making informed decisions based on risk.
If several of the following statements apply to your organisation, additional preparation may be worthwhile before beginning certification:
✅ Policies haven't been reviewed in the last 12 months
✅ Cybersecurity responsibilities are not clearly assigned
✅ Security activities are being performed but not documented
✅ User access reviews happen informally
✅ Risks are discussed but not formally recorded
✅ Backup restores have not been tested recently
✅ Security awareness training is not tracked
✅ Documentation doesn't accurately reflect current business practices
A single tick doesn't mean certification is out of reach.
However, multiple gaps often indicate areas that would benefit from attention before an assessment.
Perhaps the most significant mistake organisations make is treating SMB1001 certification as a one-time project.
A project has a finish line.
A maturity framework doesn't.
Businesses sometimes invest significant effort preparing for an assessment, only to discover that maintaining compliance requires an ongoing commitment.
The organisations that achieve the strongest outcomes take a different approach.
They view SMB1001 as a framework for continual improvement rather than a compliance exercise.
"The organisations that perform best during assessments are usually the ones that view certification as part of an ongoing improvement journey rather than a box-ticking exercise."
Chris Mannering, Director, Step Fwd IT
| Question | If the Answer is "No"... |
|---|---|
| Can we clearly identify who owns cybersecurity governance? | Accountability may be unclear |
| Are cybersecurity policies reviewed regularly? | Documentation may need attention |
| Can we produce evidence of key security activities? | Evidence collection may be inconsistent |
| Are cybersecurity risks formally documented? | Risk management may be immature |
| Have backups been tested recently? | Recovery capability may be uncertain |
| Are user access reviews documented? | Access management controls may require improvement |
This isn't a formal assessment.
However, it provides a useful indication of where common gaps may exist.
One of the most reassuring things businesses discover about SMB1001 is that assessors are not looking for perfection.
What they want to see is evidence that cybersecurity is being approached in a structured and deliberate way.
At a high level, assessors are generally looking for:
Assessors are generally looking for consistency, reasoned decision-making and documented processes that reduce risk rather than perfection.
That's an important distinction.
Most organisations already have pieces of the puzzle in place.
The challenge is bringing them together into a framework that can be managed, reviewed and demonstrated consistently.
A lack of evidence is one of the most common issues. Many organisations perform security activities but cannot easily demonstrate that those activities have occurred.
Not necessarily. Assessments evaluate overall maturity rather than focusing on a single control in isolation.
A good starting point is to review your documentation, validate technical controls and ensure evidence is available. Our guide on How to Prepare for SMB1001 Certification explores this in more detail.
No. SMB1001 evaluates governance, risk management, documentation, accountability and technical controls.
There is some overlap, particularly around cybersecurity controls. However, SMB1001 provides a broader framework for organisational maturity and certification.
Most SMB1001 audit findings are not caused by a lack of technology.
They're caused by a lack of documentation, evidence, accountability or structure.
The businesses that perform best during certification aren't necessarily the ones with the largest IT budgets or the most sophisticated security tools.
They're the organisations that can clearly demonstrate how cybersecurity is being managed, reviewed and improved over time.
"Certification shouldn't be viewed as a test to pass. It should be viewed as an opportunity to strengthen the way your organisation manages cybersecurity."
Chris Mannering, Director, Step Fwd IT
Whether you're exploring certification for the first time or actively preparing for an upcoming assessment, understanding your current level of cybersecurity maturity is often the best place to start.
Step Fwd IT can help identify potential gaps, review existing controls and build a practical roadmap towards certification.
If you're unsure where your organisation currently stands, a readiness assessment can provide clarity before the formal certification process begins.